Optimal eavesdropping in cryptography with three-dimensional quantum states 
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We study optimal eavesdropping in quantum cryptography 
with three-dimensional systems, and show that this scheme is 
more secure against symmetric attacks than protocols using 
two-dimensional states. We generalize the according eaves- 
dropping transformation to arbitrary dimensions, and discuss 
the connection with optimal quantum cloning. 
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Quantum cryptography, as first suggested by Bennett 
and Brassard (BB84) [Q], is the experimentally most ad- 
vanced application of quantum information processing. 
Recently, the use of three-level systems rather than two- 
level systems for establishing a secure quantum key has 
been suggested ^ . The authors study the case of 4 mutu- 
ally unbiased bases, i.e. 12 basis states. They consider an 
eavesdropper that uses the most simple strategy, namely 
measuring the state and resending it. For this case they 
find that a 3-dimensional system leads to a higher secu- 
rity than a 2-dimensional one. 

In order to compare the security of different quantum 
key distribution protocols, however, one has to study the 
most general eavesdropping attack. This is the aim of our 
work. Optimal eavesdropping strategies for the BB84- 
protocol and the six state protocol have been studied in 
and respectively. 

We concentrate our attention to incoherent attacks, 
namely we assume that the eavesdropper interacts with 
a single 3-dimensional quantum system at a time. We 
study the case where the action of the eavesdropper 
disturbs all the possible quantum states by the same 
amount. Denoting with {| 0), 1 1), | 2)} a basis for the sys- 
tem, the most general unitary eavesdropping strategy for 
a set of 3-dimensional states can be written as 
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Here 1 — D is the fidelity of the state that arrives at 
Bob's site after Eve's interaction. The disturbance is 
given by D. We assume the disturbance of the two basis 
states that are orthogonal to the original to be equal: this 
symmetry is motivated by the fact that the three basis 
states should be treated in the same manner. The initial 



state of Eve's system is called | A) , and her states after 
interaction are labelled | Aq), \ Bq), ... and are normalised. 
Their dimension is not fixed. 

We have to satisfy unitarity of U. This leads to the 
constraints 
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((Bo |Ao> + (Bi \Ai)) + y (B2 IA2) = 



((C2|A2)+(Co|Ao)) + ^(Ci|Al)=0, 
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We consider the cryptographic protocol suggested in 
Ref. , where the four mutually unbiased bases are given 
by{|0),|l),|2)}, and 

{|a) = -^(|0) + |l> + |2)), 
\P)^l=i\0)+u;\l)+u;*\2)) , 
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where oj = . 

We restrict ourselves to the case of symmetric at- 
tacks, i.e. Eve is supposed to introduce an equal dis- 
turbance to all possible input states written aboveR. 



^ If the noise of the physical device is known to be symmetric, 
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We can then directly compare the security to the six 
state scheme for qubits, where only symmetric attacks 
have been studied. By imposing that the disturbance 
D ^ 1- Tr(| Ipb*), where is the reduced 

density operator of the state sent on to Bob, takes the 
same value for all 12 possible input states we derive 
the following relations that involve the scalar products of 
Eve's output states: 



y/2D{l-D)i{A, \Ao) + (Bi \Bo) + (C2 \B„) + (Ai |C2» 

+D((Ci|Co)+3(Bo|Ai))=0, (6) 
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+D{{B2\Bo)+3{Co\A2)) = , (7) 
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+D((A2|Ai)+3(Ci|B2)) = 0, (8) 
{A, \Co) + {A2 \Bo) + {Bo \Ci) 

+ {B2 \Ai) + {Ci \A2) + {Co \B2) = . (9) 

Note that both real and imaginary part of these expres- 
sions have to vanish. Writing the disturbance introduced 
through the eavesdropping transformation (|l]) as a func- 
tion of the scalar products of Eve's states, and taking 
into account unitarity (|^) and the conditions (||)-@, we 
find the following simple form: 
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where S = Re[{Ao \Bi) + {Bi [Ca) + (C2 |^o>]/3. Notice 
that in the expression for the disturbance only the scalar 
products among the eavesdropper's states | Aq), \ Bi) and 
I C2) appear, while all the others do not contribute. 

We will now derive the optimal eavesdropping trans- 
formation for a fixed value D of the disturbance, namely 
we maximise the mutual information Iae between Alice 
and Eve. (This is a standard figure of merit for the de- 
scription of the efficiency of an eavesdropping attack [^.) 
As mentioned above, the disturbance introduced by Eve 
is independent of the scalar products of her states, apart 
from the ones involving | Aq), | -Bi) and | C2). Therefore, 
for any value of Z?, Eve is free to choose those states on 
which D does not depend in such a way that she retrieves 
the maximal information. The optimal choice is to take 
all of these states orthogonal to each other, because in 
this case Eve can infer the original state sent by Alice in 
an unambiguous way from her measured state. 

We will now consider only the scalar products that 
appear in S and choose them such that the mutual infor- 



then Alice and Bob could detect an asymmetric eavesdropper 
by checking the error rate in a subset of states. Otherwise, 
the trade-off between Eve's information and the signal key is 
more compficated to handle. 



mation is maximised for fixed S*, i.e. for a given distur- 
bance D. We introduce the general parametrisation for 
the normalised auxiliary states. 
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where {| 0), | 1), | 2)} is an orthonormal basis which is or- 
thogonal to all the other auxiliary states. In order to 
treat the basis states | 0), 1 1), | 2) in the same way, we 
require that the overlaps of these three states are equal. 
We choose xa — Vb ~ zc — x, while all other coeffi- 
cients are equal. Without loss of generality we can take 
the coefficients to be real. 

With this strategy we find the optimal mutual infor- 
mation between Alice and Eve to be 



lAE = l + (l-D)[f{D)\og^f{D) 

+ (l-/(D))log3 

where f{D) is given by 
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The relation between x and D is x^ = f{D). Inserting 
this into equations ( |ll|) leads, together with the ansatz 
(|l|) and a straightforward choice of the ancilla states, 
to the explicit form of the optimal transformation. Eve 
needs to employ two three-level systems for the optimal 
attack. 

The information for Bob decreases with increasing dis- 
turbance: 

Iae = 1 + {1 - D) log^il -D) + D log:, ^ ■ (14) 

Note that we renormalized the functions given in ( p^ ) 
and (p^, as in ||^, in order to be able to directly relate 
the values to the 2-dimensional case. 

We will now compare the security of the 3-dimcnsional 
scenario as described above with the most secure 2- 
dimensional scheme, that employs six states (i.e. three 
mutually unbiased bases) The according informa- 

tion curves of both protocols arc shown in figure |l|. 

We find that the 3-dimcnsional protocol is more se- 
cure in two respects: first, the information curves for 
Bob and Eve intersect at a higher disturbance Dc than 
for the 2-dimensional case, namely Z?c,3 = 0.227, while 
Dc.2 = 0.156. In other words. Eve has to introduce more 
noise in order to gain the same information as Bob. In 
general, for disturbances D < Dc, a key distribution 
protocol can be considered secure, because Iae > Iae 
1^. Therefore, the 3-dimensional protocol is secure up 
to higher disturbances. Second, for a fixed disturbance 
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FIG. 1. Mutual information for Alice/Bob and Alice/Eve 
as a function of the disturbance, for 2-dimensional and 3-di- 
mensional quantum states. 



scalar products between | Aq), \ Bi), .... The function / is 
then given by 
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In figure ^ we plot Eve's corresponding information 
lAE,d = 1 + (1 - D)[UD) loga. fd{D) 

+ (1 log, i-^M^] , (18) 

as a function of the dimension d for a fixed value of the 
disturbance D. We conjecture that this mutual informa- 
tion is optimal when employing the maximal number of 
mutually unbiased bases for a given dimension B. 



D < Dc, Bob gets more and Eve less information than in 
the 2-dimensional case. The price that has to be payed 
for higher security is a lower efficiency: the basis for Bob 
matches the one of Alice in fewer cases than for two di- 
mensions, as the number of bases is increased. 

Notice that our derivation of the optimal eavesdrop- 
ping transformation relies on equations (|^)-(H) which 
guarantee that all the possible input states are disturbed 
in the same way. If we reduce the number of bases, not 
all of these conditions will be necessary, thus leading to 
a less simple structure of D than the one given in (10). 
This would allow a different general form of the opti- 
mal eavesdropping transformation, and a higher curve 
for Iae- The analogous behaviour was shown for the 
2-dimensional case in |^,||, where the six-state protocol 
and the BB84 scheme were compared. 

Generalising the ansatz given in (^ and the structure 
of the ancilla states as in (11) to higher dimensions, we 
find a lower bound on the eavesdropper's information for 
quantum cryptography with d-dimensional systems. The 
general ansatz is then 
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(The alphabet denoting Eve's states is supposed to con- 
tain d letters.) The according generalized formula for the 
disturbance as a function of the scalar products is 
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d-S{d~l) ' 
where S is now the real part of the average of all possible 



FIG. 2. Mutual information between Eve and Alice as a 
function of the dimension, for D = 0.1. 

Finally, we discuss the connection between optimal 
eavesdropping strategies and optimal cloning transforma- 
tions. The information that Eve can gain is restricted by 
the laws of quantum mechanics, namely the no-cloning 
theorem [Q. Let us point out, however, that there is, 
in general, no direct connection between limits on the 
cloning fidelity for a given d-dimensional state, and the 
intersection of the information curves of Bob and Eve. 
The reason is that approximate cloning transformations 
1^ are only a subset of our family of transformations U 
given in eq. (0), because an additional symmetry be- 
tween the first of Eve's states and Bob's state is required 
for cloning. Indeed, if Eve would read only the first of her 
two states, the disturbance for the intersection between 
the two resulting information curves would correspond 
to the fidelity of the optimal doner. Reading both states 
increases her information. Therefore, the knowledge of 
cloning transformations for d-dimensional systems Q al- 
lows only to find a lower bound on Eve's information at 
a given disturbance. 

In summary, we have found a remarkable feature of 
higher-dimensional quantum systems: we have proven 
analytically for dimension d — 3 that the most gen- 
eral symmetric attack of an eavesdropper gives her less 
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information than in the case of qubits. Therefore a 
three-dimensional scheme offers higher security than two- 
dimensional systems. We generalised the upper limit for 
Eve's information Iae from ci = 3 to higher dimensions: 
this limit decreases with the dimension, and numerically 
we find that it reaches Iae = D in the limit d oo. 
As quantum cryptography is the most advanced tech- 
nology in quantum information, and security issues play 
a fundamental role in any study of cryptography, it is 
important to discuss quantitative properties of the secu- 
rity in quantum key distribution: here quantity becomes 
quality. 

While completing this manuscript we learnt about re- 
lated work by M. Bourennane et al ||l0|] . 
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